Data Processing Agreement

Effective Date: 7 September 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Setten Company Limited (“Setten”, “we”, “us”, “our”) and the customer that uses the Setten platform (“Customer”, “you”).

This DPA applies when Setten processes personal data in Customer Content on behalf of a Customer as a processor or subprocessor. It does not apply to personal data that Setten processes as a controller for its own business purposes, which is described in the Privacy Policy.

If this DPA conflicts with the Terms of Service, this DPA controls for the processing of Customer Personal Data. If the Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses control for the relevant transfer.

1. Definitions

  • “Customer Personal Data” means personal data contained in Customer Content that Setten processes on behalf of Customer through the Service.
  • “Data Protection Law” means privacy, data protection, and data security laws that apply to the processing of Customer Personal Data, including the GDPR and UK GDPR where applicable.
  • “GDPR” means Regulation (EU) 2016/679.
  • “SCCs” means the European Commission’s standard contractual clauses for international transfers of personal data adopted under Commission Implementing Decision (EU) 2021/914, as updated or replaced.
  • “Security Incident” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data. It does not include unsuccessful attempts that do not compromise Customer Personal Data.
  • “Subprocessor” means a third party engaged by Setten to process Customer Personal Data on Setten’s behalf.

Capitalised terms not defined in this DPA have the meaning given in the Terms of Service.

2. Roles and Instructions

2.1 Roles. Customer acts as controller and Setten as processor of Customer Personal Data. Where Customer processes that data on behalf of another controller, Customer acts as processor and Setten as subprocessor.

2.2 Customer instructions. Customer instructs Setten to process Customer Personal Data as necessary to provide, secure, maintain, and support the Service, to comply with the Terms of Service and this DPA, and as otherwise configured or requested by Customer and its Users through the Service.

2.3 Additional instructions. Additional instructions must be consistent with the Terms of Service and this DPA. Setten may charge reasonable fees or decline an additional instruction if it requires processing outside the scope of the Service. If Setten believes an instruction infringes Data Protection Law, Setten will inform Customer unless prohibited by law.

2.4 Customer responsibilities. Customer is responsible for: (a) ensuring its instructions are lawful; (b) having the rights and permissions needed for Customer Personal Data; (c) configuring workspace permissions appropriately; and (d) meeting the recording requirements in Section 9 of the Terms of Service.

3. Details of Processing

3.1 Subject matter. Setten processes Customer Personal Data to provide the Setten workspace platform, including project and task management, calendar and scheduling, meeting recording and transcription, document and file management, search, notifications, AI summaries and assistance, support, backup, and security.

3.2 Duration. Setten processes Customer Personal Data for the term of Customer’s subscription and for the deletion, export, backup, and legal retention periods described in the Privacy Policy.

3.3 Nature and purpose. Hosting, storage, transmission, retrieval, display, search indexing, transcription, summarisation, generation of AI outputs, notification delivery, backup, support, troubleshooting, security monitoring, abuse prevention, and deletion.

3.4 Categories of data subjects. Customer’s Users; employees, contractors, collaborators, customers, prospects, suppliers, and other contacts of Customer; meeting participants; booking guests; calendar attendees; message correspondents; and individuals referenced in Customer Content.

3.5 Categories of personal data. Account identifiers and contact details; workspace membership and permissions; calendar event and availability data; booking details; project, task, comment, document, file, and message content; meeting audio and video; transcripts; speaker labels; timestamps; prompts; AI-generated output; support data; security and audit logs; consent records submitted to or generated through the Service; and any other personal data Customer or its Users submit to the Service.

3.6 Sensitive data. The Service does not require sensitive personal data. Customer may choose to include sensitive data in Customer Content, and meeting recordings may include voice, image, biometric, health, employment, or other sensitive information. Customer is responsible for processing sensitive data lawfully.

3.7 Frequency. Processing occurs continuously while Customer uses the Service.

4. Setten Obligations

Setten will:

  • process Customer Personal Data only on documented instructions from Customer, including for international transfers, unless required by law;
  • ensure personnel authorised to process Customer Personal Data are bound by confidentiality obligations;
  • implement and maintain the security measures described in Section 6;
  • assist Customer, taking into account the nature of the processing, with data subject requests where Customer cannot fulfil the request through the Service;
  • assist Customer with security, breach notification, data protection impact assessment, and prior consultation obligations, taking into account the nature of the processing and information available to Setten;
  • notify Customer without undue delay after becoming aware of a Security Incident;
  • delete or return Customer Personal Data after the end of the Service in accordance with Section 8; and
  • make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits as described in Section 7.

5. Subprocessors

5.1 Authorisation. Customer gives Setten general written authorisation to engage Subprocessors to process Customer Personal Data.

5.2 Current list. The current Subprocessors are listed on the Subprocessors page, including their processing activities, data processed, and locations.

5.3 New Subprocessors. If Setten adds or replaces a Subprocessor that processes Customer Content, Setten will update the Subprocessors page and give notice by email or in-product notice before the change takes effect, where reasonably practicable.

5.4 Objection. Customer may object to a new Subprocessor on reasonable data protection grounds by emailing hi@settenhq.com within 30 days after notice. Setten and Customer will work in good faith to address the objection. If the objection cannot be resolved, Customer may terminate the affected part of the Service, and Setten will refund any prepaid unused fees for that affected part.

5.5 Subprocessor obligations. Setten will enter into a written agreement with each Subprocessor imposing data protection obligations no less protective than those in this DPA, to the extent applicable to the Subprocessor’s services. Setten remains responsible for each Subprocessor’s performance of those obligations.

6. Security Measures

Setten maintains technical and organisational measures appropriate to the risk of the processing, including:

  • encryption in transit using TLS;
  • network isolation for systems that store personal data;
  • role-based access controls and least-privilege access for personnel;
  • salted one-way password hashing;
  • logging and monitoring of access and administrative actions;
  • encrypted backups;
  • vulnerability and incident response processes; and
  • contractual confidentiality and security obligations for Subprocessors.

Customer is responsible for securing its own accounts, devices, networks, integrations, and workspace permission settings.

7. Audits and Information

Upon written request, Setten will provide information reasonably necessary to demonstrate compliance with this DPA. Customer may conduct, or appoint an independent auditor to conduct, an audit no more than once every 12 months, unless required by Data Protection Law, a supervisory authority, or following a Security Incident.

Audits must be conducted on reasonable advance notice, during normal business hours, without disrupting the Service or compromising another customer’s data or Setten’s security, and subject to confidentiality obligations. Setten may satisfy an audit request by providing current security documentation, third-party audit reports, certifications, or written responses where those materials provide the requested assurance.

8. Return and Deletion

During the subscription term, Customer may export or delete Customer Personal Data through the Service where available.

After termination or expiry of the Service, Setten will retain Customer Content for 30 days so Customer may request export, then delete it from active systems. Residual copies are purged from encrypted backups within 90 days, unless retention is required by law, needed to resolve a dispute, or necessary to establish, exercise, or defend legal claims.

9. International Transfers

Setten is established in Vietnam and uses Subprocessors in the locations listed on the Subprocessors page. Customer Personal Data may therefore be transferred to and processed in countries outside Customer’s country.

Where Data Protection Law requires a transfer mechanism for Customer Personal Data transferred from the European Economic Area, United Kingdom, or Switzerland to a country without an applicable adequacy decision, the parties agree that:

  • for transfers from Customer as controller to Setten as processor, the SCCs apply using Module Two;
  • for transfers from Customer as processor to Setten as subprocessor, the SCCs apply using Module Three;
  • the SCCs are incorporated by reference into this DPA;
  • the optional docking clause in Clause 7 does not apply;
  • Clause 9 Option 2 applies, with Subprocessor notice and objection handled under Section 5;
  • the optional language in Clause 11 does not apply;
  • Clause 17 is governed by the law of Ireland and Clause 18 gives jurisdiction to the courts of Ireland, where required for the SCCs to be effective; and
  • the SCC Annexes are completed by Sections 3, 5, 6, and this Section 9 of this DPA, together with the Subprocessors page.

For transfers from the United Kingdom, the UK International Data Transfer Addendum to the EU SCCs applies where required. For transfers from Switzerland, references in the SCCs to the GDPR are interpreted to include the Swiss Federal Act on Data Protection where required, and the Swiss Federal Data Protection and Information Commissioner is the competent authority where applicable.

10. Security Incident Notice

Setten will notify Customer without undue delay after becoming aware of a Security Incident. The notice will include information reasonably available to Setten, such as the nature of the incident, categories of data affected, likely consequences, mitigation steps taken or proposed, and a contact point for follow-up.

Setten’s notice of a Security Incident is not an acknowledgement of fault or liability.

11. Liability

Each party’s liability under this DPA is subject to the exclusions and limitations of liability in the Terms of Service, unless Data Protection Law requires otherwise.

12. Changes to this DPA

Setten may update this DPA from time to time. If a change materially reduces Setten’s obligations for Customer Personal Data, Setten will give at least 30 days’ notice by email or in-product notice before the change takes effect, unless the change is required by law or needed to address a security risk.